Files
securebit-chat/tests/version-consistency.test.mjs
T
lockbitchat 3212138a0d
CodeQL Analysis / Analyze CodeQL (push) Waiting to run
Deploy Application / deploy (push) Waiting to run
Mirror to Codeberg / mirror (push) Waiting to run
Mirror to PrivacyGuides / mirror (push) Waiting to run
docs: reorganise documentation; derive header version from package.json; release v5.7.2
No protocol or message-protection changes.

The version in the application header was a literal and had fallen behind,
showing v5.6.0 while running 5.7.1. It now comes from package.json, and a test
fails if a hard-coded one reappears or if meta.json, the README badge, the
changelog and the docs disagree about the release.

Documentation reorganised so that everything technical lives in doc/ with an
index, and the root keeps only what belongs there by convention: README,
SECURITY, CHANGELOG and LICENSE.

- SECURITY.md rewritten. It listed a supported release line three major versions
  out of date and made claims the software does not make. It now states what is
  guaranteed, what is not, and how to report a problem.
- SECURITY_DISCLAIMER.md and RESPONSIBLE_USE.md merged into doc/USE-POLICY.md,
  which says what the software cannot protect against rather than listing
  generic advice.
- doc/SECURITY-ARCHITECTURE.md renamed to doc/ARCHITECTURE.md and rewritten
  around the session lifecycle, what verification gates, and how recovery works.
- doc/CRYPTOGRAPHY.md rewritten: key schedule, the Double Ratchet, framing, and
  memory handling, with values taken from the source rather than restated.
- doc/CONFIGURATION.md rewritten with the real file-type policy, ICE and TURN
  guidance, and the deployment caching rules that matter.
- docs/webrtc-config.md moved to doc/CALLS.md and rewritten; the obsolete
  docs/webrtc-audit.md, a working document full of stale line numbers, removed
  along with the docs/ directory.
- doc/CONTRIBUTING.md records what the recent regressions taught us about
  writing tests that can actually fail.
- doc/README.md added as an index.

Internal security review notes are excluded from the repository via .gitignore.
Those describe attack paths against specific releases in enough detail to
reproduce them, which is useful privately and harmful in public while users are
still updating.
2026-08-05 23:54:50 -04:00

69 lines
2.4 KiB
JavaScript

// The version is stated in several places that a release has to keep in step.
// The one in the header was hard-coded and drifted: the application advertised
// v5.6.0 while running 5.7.1. Anything a person has to remember at release time
// eventually gets forgotten, so these assertions do the remembering.
import assert from 'node:assert/strict';
import { readFileSync } from 'node:fs';
const read = (rel) => readFileSync(new URL(`../${rel}`, import.meta.url), 'utf8');
const pkg = JSON.parse(read('package.json'));
const version = pkg.version;
assert.match(version, /^\d+\.\d+\.\d+$/, 'package.json must carry a plain semver version');
// package.json is the single source of truth. The header must derive from it
// rather than restate it, so no release step is needed to keep them together.
{
const header = read('src/components/ui/Header.jsx');
assert.match(
header,
/import\s*\{\s*version[^}]*\}\s*from\s*['"][^'"]*package\.json['"]/,
'the header must import the version from package.json'
);
assert.equal(
/['"]v\d+\.\d+\.\d+['"]/.test(header),
false,
'the header must not contain a hard-coded version literal'
);
}
// meta.json drives the update check and is regenerated by the build. If it is
// behind, the build was not re-run before committing and clients will not be
// told an update exists.
{
const meta = JSON.parse(read('meta.json'));
assert.equal(
meta.appVersion, version,
'meta.json is stale: run `npm run build` before committing a version bump'
);
}
// The README badge and the changelog are read by people deciding whether to
// update, so a mismatch there is a mismatch in what we are telling them.
{
const readme = read('README.md');
assert.ok(
readme.includes(`version-${version}-`),
`the README version badge must show ${version}`
);
const changelog = read('CHANGELOG.md');
const firstEntry = changelog.split('\n').find((line) => line.startsWith('## v'));
assert.ok(
firstEntry && firstEntry.startsWith(`## v${version}`),
`the newest changelog entry must be v${version}, found: ${firstEntry}`
);
}
// Documentation quotes the release it describes.
{
const crypto = read('doc/CRYPTOGRAPHY.md');
assert.ok(
crypto.includes(version),
`doc/CRYPTOGRAPHY.md must reference the current release (${version})`
);
}
console.log('version-consistency.test.mjs: all assertions passed');